Claudeforce settles a question Salesforce has been answering provisionally for ten years. Einstein, Copilot and Agentforce each brought model capability into the product, where Salesforce owned the intelligence, the experience, and the distance between them. Salesforce in Claude sends the product outward instead, exposing data, workflows, business logic and permissions to a model running elsewhere. The arrangement holds regardless of how good models become, which is the first time that has been true.

Each earlier product was a sensible answer to what was available. Einstein was built when machine learning meant scoring and classification, so it scored leads and predicted close dates, and it sat inside the objects because that is where the features lived. Agentforce arrived when models could hold a conversation and complete an action, so it received defined topics and permitted actions and worked inside a boundary. Both were shipped into a market where the capability curve moved faster than any release cycle could follow, and products built to a moving specification tend to be superseded by the thing that made them possible.

What has actually settled

Model capability now exceeds what a defined set of conversational paths can spend. That single fact changes the binding constraint from intelligence to access, and once access is the constraint, the party holding the record has the durable position.

Headless 360 is what makes access practical. Data, applications, workflows, agents and the governance around them are exposed as capabilities an external system calls over MCP, without an interface and without custom integration work. The thirty seven sales skills shipping with Salesforce in Claude are written instruction rather than compiled product, and Salesforce has said the same capabilities are open to any developer building their own. A firm that knows how its revenue actually arrives can describe that in words and have it work the same way.

Model quality compounds for whoever builds models. The record, the permissions and the rules compound for whoever holds them.

The commercial reasoning is clearer than anything that preceded it. Salesforce stops competing on model quality, which was never going to be its durable asset, and competes on deterministic truth, an enforced permission model, and twenty seven years of business logic. Attached to frontier reasoning, those are worth more than they were as the setting for a proprietary assistant. Anthropic gets grounded context. Neither party is waiting on the other to catch up.

There is a practical consequence for firms that watched the previous cycle without committing to it. Nothing built during that period needs unwinding to adopt this. The permission model already carries across, the object model is the same object model, and the preparation that matters is work that was worth doing regardless.

The questions the arrangement raises

Sending the product outward moves the governance conversation to different ground.

Data residency is the open item. Salesforce states that controls over where data is stored and who can access it are being developed with Anthropic. Firms holding data locally will want a position on that before production use, because Australian privacy law allocates responsibility for overseas disclosure rather than transferring it, and the accountability stays with the disclosing entity.

Zero data retention applies on Sonnet, Opus and Haiku, which addresses retention. Processing is a separate matter, since content transits and is processed to produce an answer, and due diligence responses are more accurate when the two are described separately.

Write controls deserve deliberate configuration rather than default acceptance. Record content includes text the organisation did not author, arriving through web forms, inbound email and case comments, and a model reading those fields with send capability is reading instructions from whoever wrote them. Salesforce provides the right controls here. Claude can confirm before emailing anyone external, and record updates are scoped to the named field. Both settings are choices, and both are worth making once, deliberately, at the start.

Audit attribution follows from the design working as intended. Actions run under the authenticated person’s permissions, which is what removes the need for a new permissions model, and it also means the trail records a person where an agent acted. Firms carrying supervision or record keeping obligations will want to establish how that reads before rollout.

Salesforce in Claude is available to selected pilot customers now, with open beta planned for September and the remaining clouds listed without dates. Sales ships first.

Strategy is usually described as the ability to move quickly. It is more often the ability to stop moving, having found the position that survives the next thing.


Q: Does Claudeforce replace Agentforce?

No. Agentforce runs autonomous agents inside Salesforce channels, largely for service and customer facing work. Salesforce in Claude gives sellers conversational access to their own pipeline through a plugin. Both call the same data and the same permission model, and the choice is about which task belongs where.

Q: What preparation actually matters before connecting Salesforce to a model?

A review of what existing sharing rules currently permit, since they become the reading model, and an honest look at whether sales activity has been logged consistently enough to reason over. Both are worth doing independently of any AI decision, which makes them low risk preparation.

Q: Where is Salesforce data processed when Claude answers a question?

Record content is sent to Anthropic’s model service to generate the answer. Zero data retention applies on Sonnet, Opus and Haiku. Controls covering storage location and access are described by Salesforce as still in development, so residency requirements should be confirmed directly before production use.

Q: Can the thirty seven sales skills be adapted for a business that does not sell software?

Yes. The skills are written instruction, and Salesforce has confirmed the underlying capabilities are open to any developer building their own. Firms whose revenue arrives through platforms, approved lists or ratings decisions will find some skills fit as shipped and others are worth describing again.